Again, what is the purpose of vMX? I see it more as a transit gateway to access your resources within Azure, AWS, etc.
Do you want to expose your applications to the internet and use vMX to do some type of filtering? Or is it to limit what your machines within Azure can access?
It can handle like a firewall, but it would be good to understand its purpose first.
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.